What Is 23 NYCRR 500 (New York DFS Cybersecurity Regulation)?

Also called: NYDFS Part 500, NYDFS Cybersecurity Regulation, Part 500

Related problems: We hold a New York insurance, banking or money transmitter license and must certify compliance every year; Need MFA, asset inventory and annual penetration testing to satisfy our regulator; Have to hold our IT and cloud vendors to written security requirements; Not sure whether we qualify for a limited exemption

The New York DFS Cybersecurity Regulation, 23 NYCRR Part 500, is a rule from the New York State Department of Financial Services (DFS) that requires the financial services companies it licenses or regulates to maintain a risk-based cybersecurity program, meet specific control requirements and certify compliance each year. First issued in 2017 and significantly amended in 2023, it covers organizations such as insurers, insurance agencies, banks, lenders and money transmitters operating under New York authorizations. Its requirements reach into IT providers through third-party service provider rules. This entry is an overview for buyers, not legal advice; confirm current requirements with DFS guidance or counsel.

At a glance

  • Applies to entities operating under a license, registration, charter or similar authorization under New York’s Banking, Insurance or Financial Services laws.
  • Requires a cybersecurity program and policies based on a risk assessment and, for most covered entities, a CISO and controls such as MFA, asset inventory, encryption, logging, training and testing.
  • Reportable incidents generally go to DFS within 72 hours of determination; extortion payments have separate notice rules.
  • Each covered entity files an annual certification of material compliance or an acknowledgment of noncompliance by April 15.
  • Larger “Class A” companies face added requirements, while smaller entities may qualify for a limited exemption.

What problem it solves

Financial services firms hold sensitive personal and financial data and are frequent targets for ransomware, fraud and account takeover. Before Part 500, cybersecurity expectations for many state-licensed firms, especially smaller insurers and agencies, were general and uneven. DFS set specific minimum requirements and made senior leaders personally sign off on compliance.

The regulation also addresses a weak point: vendors. Many incidents start at a service provider, so Part 500 requires covered entities to set minimum security practices for their providers and check them, which brings third-party risk management (TPRM) into scope.

How it works

Program and governance. Each covered entity maintains a cybersecurity program and written policies approved by senior leadership, informed by a risk assessment that is reviewed periodically. Unless an exemption removes the requirement, a CISO, who can be employed by an affiliate or a third party such as a virtual CISO provider, reports to the board or senior governing body.

Technical controls. Requirements include multi-factor authentication (MFA) for individuals accessing information systems (with a narrower scope for entities under the limited exemption and room for CISO-approved compensating controls), an asset inventory, access privilege limits and reviews, encryption of nonpublic information, audit trails, secure application development practices, monitoring, training and data disposal.

Testing. Covered entities outside the limited exemption conduct penetration testing at least annually by a qualified internal or external party, plus vulnerability scanning at a frequency set by their risk assessment and after material changes.

Third-party service providers. Written policies identify and assess providers, set minimum security practices, require due diligence and periodic reassessment, and address MFA, encryption, incident notice and representations in contracts or due diligence.

Incident response and reporting. Entities keep incident response and business continuity plans, notify DFS of reportable incidents generally within 72 hours of determining they occurred, report extortion payments within 24 hours with a written explanation within 30 days, and file the annual compliance notice.

Covered entity categories

Part 500’s main structure is by entity size and type. The thresholds below reflect the current amended regulation; confirm with DFS or counsel before relying on them.

Category Who it applies to What’s required Typical evidence
Class A company Covered entities with at least $20 million in gross annual revenue in each of the last two fiscal years from all of the covered entity’s business operations plus the New York business operations of its affiliates, and either more than 2,000 employees averaged over the last two fiscal years or more than $1 billion in gross annual revenue in each of the last two fiscal years, in both cases counting the covered entity and its affiliates wherever located (affiliates count only if they share information systems, cybersecurity resources or part of a cybersecurity program with the covered entity) Full requirements plus added duties, including independent audits of the cybersecurity program, endpoint detection and response, and centralized logging and alerting (or CISO-approved equivalents) Independent audit reports, annual certification, risk assessments, test results
Standard covered entity Covered entities that are not Class A and don’t qualify for an exemption Full program, CISO, controls, testing, notices and annual compliance filing Policies, risk assessment, penetration test and scan results, MFA and asset inventory evidence, annual certification
Limited exemption Covered entities meeting any one of: fewer than 20 employees and independent contractors of the covered entity and its affiliates; less than $7.5 million in gross annual revenue in each of the last three fiscal years from all of the covered entity’s business operations plus the New York business operations of its affiliates; or less than $15 million in year-end total assets, calculated under GAAP and including all affiliates’ assets A reduced set of requirements: still a program, policies, risk assessment, access controls, MFA (for remote access and privileged accounts), notices and the annual filing, among others; no CISO requirement; notice of exemption filed with DFS Notice of exemption, policies, risk assessment, annual filing
Other exemptions For example, entities fully covered by an affiliated covered entity’s program, or entities that don’t use information systems or hold nonpublic information Varies by exemption; a notice of exemption is generally required Notice of exemption, documentation of the basis

When it matters for buyers

  • When you hold a New York financial services authorization. Your cloud, MSP, UCaaS and contact center providers need to fit your Part 500 program.
  • When signing or renewing IT providers. Expect to document due diligence and contract terms on access, MFA, encryption and incident notice.
  • Before the April 15 filing. Senior leaders sign, so they need evidence, not assumptions.
  • When an incident hits a provider. Your 72-hour clock can apply to incidents at a third-party service provider.

Our governance, risk and compliance overview covers program-building, vCISO and assessment help.

Questions to ask vendors

  • How quickly will you notify us of a cybersecurity event affecting our systems or nonpublic information, so we can meet our 72-hour obligation?
  • Do you enforce MFA for everyone who can access our data, including your own staff?
  • Is our nonpublic information encrypted in transit and at rest, and who controls the keys?
  • What independent security reports can you share, and are they scoped to this service?
  • Will you accept contract terms covering security representations, incident notice and cooperation with DFS inquiries?
  • Can you supply evidence that supports our annual certification?

How it differs from GLBA

The Gramm-Leach-Bliley Act (GLBA) is a US federal law that sets privacy and safeguards duties for financial institutions nationwide, enforced by different federal and state regulators. Part 500 is a New York regulation that applies to DFS-licensed entities and is more prescriptive in places, with annual executive certification and specific notice deadlines. Many New York-licensed firms are subject to both. Public companies may also face the SEC cybersecurity disclosure rules, and many firms use the NIST Cybersecurity Framework (NIST CSF) to organize a program that meets all of them.

Frequently Asked Questions

Who has to comply with 23 NYCRR 500?
Organizations operating under, or required to operate under, a license, registration, charter or similar authorization under New York's Banking, Insurance or Financial Services laws, such as many insurers, insurance agencies and brokers, banks, lenders and money transmitters. This applies even if another agency also regulates them. Confirm your status with counsel; this is not legal advice.
When do we have to notify DFS of a cybersecurity incident?
Under the current regulation, generally no later than 72 hours after determining that a reportable cybersecurity incident has occurred, including at an affiliate or third-party service provider. Extortion payments have their own notice within 24 hours and a written explanation within 30 days.
What is the annual filing?
By April 15 each year, covered entities submit either a certification that they materially complied during the prior calendar year or an acknowledgment of noncompliance that identifies the gaps and the remediation plan. It is signed by the highest-ranking executive and the CISO or senior officer responsible for cybersecurity.
Does the regulation apply to our IT vendors?
Not directly, unless they are covered entities themselves. But covered entities must have written third-party service provider policies, so vendors are asked for due diligence evidence and contract terms on access controls, MFA, encryption and incident notice.
Is there an exemption for small companies?
There is a limited exemption, not a full one, for covered entities below thresholds on headcount, gross annual revenue or year-end total assets, each measured as the regulation defines it. Exempt entities still need a program, policies, risk assessment and several other requirements, and must file a notice of exemption. Check the current thresholds with DFS or counsel.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.